- State
- CT
- Covered entity type
- Healthcare Provider
- Individuals affected
- 40,491
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On April 14, 2016, the covered entity (CE), Stamford Podiatry Group P.C., learned that an unauthorized individual(s) had gained privileged access and compromised its computer server between February 2, 2016 and April 14, 2016, including its electronic record database. The breach affected 40,491 individuals and included demographic, financial, and clinical information. OCR reviewed the CE's policies and procedures as relevant to this breach and they appeared to be in compliance with the Privacy and Security Rule. The CE retrained staff, implemented an upgraded, more secure data backup solution, and enhanced safeguards for its information technology (IT) system, including completely rebuilding its IT operating environment. The CE implemented new risk management policies and plans, improved its processes for managing and monitoring its vendors, and reduced the amount of PHI and personally identifiable information in its possession. OCR obtained assurances that the CE provided breach notification to affected individuals and the media in accordance with the Breach Notification Rule.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.